ExecuteMalware

2020-07-17 ZLoader IOCs

Jul 17th, 2020
2,614
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.07 KB | None | 0 0
  1.  
  2. THREAT ATTRIBUTION: ZLOADER
  3.  
  4. SUBJECTS OBSERVED
  5. Agreement ID 948 data
  6. Detailed Receipt number 739
  7. Tips on invoice - No. 631
  8.  
  9. SENDERS OBSERVED
  10. cadboroughvimlip4@aol[.]com
  11. goignusglusx@aol[.]com
  12. werberht_erok@aol[.]com
  13.  
  14. EXCEL FILE NAMES
  15. IBB-739[.]xls
  16. XFG948[.]xls
  17. ZYI-631[.]xls
  18.  
  19. EXCEL FILE HASHES
  20. 6f2f90e46dfe67a3837abc6150e7153c
  21. 75c347ee5c88139b0d70c10b57819a98
  22. 7c0906abafecad2c7cf6c1271d639fa1
  23.  
  24. ZLOADER PAYLOAD URLs
  25. hxxps://6730dartmouth[.]com/wp-keys[.]php
  26. hxxps://akcje[.]browarbrodacz[.]pl/wp-keys[.]php
  27. hxxp://myadvision[.]com/wp-keys[.]php
  28. hxxps://scoutadvisors[.]com/wp-keys[.]php
  29.  
  30. ZLOADER C2s
  31. hxxp://myadvision[.]com/wp-parsing[.]php
  32. hxxps://6730dartmouth[.]com/wp-parsing[.]php
  33. hxxps://akcje[.]browarbrodacz[.]pl/wp-parsing[.]php
  34. hxxps://winfectsolutions[.]com/wp-parsing[.]php
  35. hxxps://wadapptanara[.]tk/wp-parsing[.]php
  36. hxxps://fortsanmanesilink[.]ga/wp-parsing[.]php
  37.  
  38. SUPPORTING EVIDENCE
  39. https://pastebin.com/MtE7jpYB
  40. https://app.any.run/tasks/5f826b3c-11b7-4fd9-8193-ce9eacf7cc81#
  41. https://app.any.run/tasks/8b72d71a-0d33-4b77-8f6b-f7e9dcad0403
Add Comment
Please, Sign In to add comment